Junglewise Threat Intelligence

CVE-2026-3055: Citrix NetScaler out-of-bounds read in SAML IdP

CVE-2026-3055 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-03-30

Executive brief

Citrix NetScaler ADC and Gateway appliances, which manage network traffic and remote access, contain a critical vulnerability when used for single sign-on (SAML). An attacker can remotely access sensitive information from the device's memory, potentially leading to full system compromise or data theft. This vulnerability is actively being exploited in the wild, making immediate patching essential to protect corporate networks.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Citrix NetScaler ADC and Gateway due to insufficient input validation when the device is configured as a SAML Identity Provider (IdP). A remote, unauthenticated attacker can exploit this flaw over the network to read sensitive data from the appliance's memory. This memory overread can potentially lead to the disclosure of session tokens, private keys, or other sensitive information, facilitating further compromise. The vulnerability is confirmed to be exploited in the wild and affects multiple versions including 13.1 and 14.1; patches are available from the vendor.

Affected products

  • Citrix NetScaler ADC 13.1 before 13.1-62.23, 14.1 before 14.1-60.58, 13.1 FIPS before 13.1-37.262, 13.1 NDcPP before 13.1-37.262
  • Citrix NetScaler Gateway 13.1 before 13.1-62.23, 14.1 before 14.1-60.58

Timeline

  • 2026-03-23: disclosed: Initial CVE entry received from NetScaler
  • 2026-03-30: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2026-03-30: advisory: Vendor advisory CTX696300 published
  • 2026-03-31: patched: NIST updated with specific patched version ranges

Related threats